Home | History | Annotate | Line # | Download | only in kern
subr_asan.c revision 1.9.2.3
      1 /*	$NetBSD: subr_asan.c,v 1.9.2.3 2020/04/13 08:05:04 martin Exp $	*/
      2 
      3 /*
      4  * Copyright (c) 2018-2020 The NetBSD Foundation, Inc.
      5  * All rights reserved.
      6  *
      7  * This code is derived from software contributed to The NetBSD Foundation
      8  * by Maxime Villard.
      9  *
     10  * Redistribution and use in source and binary forms, with or without
     11  * modification, are permitted provided that the following conditions
     12  * are met:
     13  * 1. Redistributions of source code must retain the above copyright
     14  *    notice, this list of conditions and the following disclaimer.
     15  * 2. Redistributions in binary form must reproduce the above copyright
     16  *    notice, this list of conditions and the following disclaimer in the
     17  *    documentation and/or other materials provided with the distribution.
     18  *
     19  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
     20  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
     21  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     22  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
     23  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
     24  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
     25  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
     26  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
     27  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     28  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
     29  * POSSIBILITY OF SUCH DAMAGE.
     30  */
     31 
     32 #include <sys/cdefs.h>
     33 __KERNEL_RCSID(0, "$NetBSD: subr_asan.c,v 1.9.2.3 2020/04/13 08:05:04 martin Exp $");
     34 
     35 #include <sys/param.h>
     36 #include <sys/device.h>
     37 #include <sys/kernel.h>
     38 #include <sys/param.h>
     39 #include <sys/conf.h>
     40 #include <sys/systm.h>
     41 #include <sys/types.h>
     42 #include <sys/asan.h>
     43 
     44 #include <uvm/uvm.h>
     45 
     46 #ifdef KASAN_PANIC
     47 #define REPORT panic
     48 #else
     49 #define REPORT printf
     50 #endif
     51 
     52 /* ASAN constants. Part of the compiler ABI. */
     53 #define KASAN_SHADOW_SCALE_SHIFT	3
     54 #define KASAN_SHADOW_SCALE_SIZE		(1UL << KASAN_SHADOW_SCALE_SHIFT)
     55 #define KASAN_SHADOW_MASK		(KASAN_SHADOW_SCALE_SIZE - 1)
     56 #define KASAN_ALLOCA_SCALE_SIZE		32
     57 
     58 /* The MD code. */
     59 #include <machine/asan.h>
     60 
     61 /* ASAN ABI version. */
     62 #if defined(__clang__) && (__clang_major__ - 0 >= 6)
     63 #define ASAN_ABI_VERSION	8
     64 #elif __GNUC_PREREQ__(7, 1) && !defined(__clang__)
     65 #define ASAN_ABI_VERSION	8
     66 #elif __GNUC_PREREQ__(6, 1) && !defined(__clang__)
     67 #define ASAN_ABI_VERSION	6
     68 #else
     69 #error "Unsupported compiler version"
     70 #endif
     71 
     72 #define __RET_ADDR	(unsigned long)__builtin_return_address(0)
     73 
     74 /* Global variable descriptor. Part of the compiler ABI.  */
     75 struct __asan_global_source_location {
     76 	const char *filename;
     77 	int line_no;
     78 	int column_no;
     79 };
     80 struct __asan_global {
     81 	const void *beg;		/* address of the global variable */
     82 	size_t size;			/* size of the global variable */
     83 	size_t size_with_redzone;	/* size with the redzone */
     84 	const void *name;		/* name of the variable */
     85 	const void *module_name;	/* name of the module where the var is declared */
     86 	unsigned long has_dynamic_init;	/* the var has dyn initializer (c++) */
     87 	struct __asan_global_source_location *location;
     88 #if ASAN_ABI_VERSION >= 7
     89 	uintptr_t odr_indicator;	/* the address of the ODR indicator symbol */
     90 #endif
     91 };
     92 
     93 static bool kasan_enabled __read_mostly = false;
     94 
     95 /* -------------------------------------------------------------------------- */
     96 
     97 void
     98 kasan_shadow_map(void *addr, size_t size)
     99 {
    100 	size_t sz, npages, i;
    101 	vaddr_t sva, eva;
    102 
    103 	KASSERT((vaddr_t)addr % KASAN_SHADOW_SCALE_SIZE == 0);
    104 
    105 	sz = roundup(size, KASAN_SHADOW_SCALE_SIZE) / KASAN_SHADOW_SCALE_SIZE;
    106 
    107 	sva = (vaddr_t)kasan_md_addr_to_shad(addr);
    108 	eva = (vaddr_t)kasan_md_addr_to_shad(addr) + sz;
    109 
    110 	sva = rounddown(sva, PAGE_SIZE);
    111 	eva = roundup(eva, PAGE_SIZE);
    112 
    113 	npages = (eva - sva) / PAGE_SIZE;
    114 
    115 	KASSERT(sva >= KASAN_MD_SHADOW_START && eva < KASAN_MD_SHADOW_END);
    116 
    117 	for (i = 0; i < npages; i++) {
    118 		kasan_md_shadow_map_page(sva + i * PAGE_SIZE);
    119 	}
    120 }
    121 
    122 static void
    123 kasan_ctors(void)
    124 {
    125 	extern uint64_t __CTOR_LIST__, __CTOR_END__;
    126 	size_t nentries, i;
    127 	uint64_t *ptr;
    128 
    129 	nentries = ((size_t)&__CTOR_END__ - (size_t)&__CTOR_LIST__) /
    130 	    sizeof(uintptr_t);
    131 
    132 	ptr = &__CTOR_LIST__;
    133 	for (i = 0; i < nentries; i++) {
    134 		void (*func)(void);
    135 
    136 		func = (void *)(*ptr);
    137 		(*func)();
    138 
    139 		ptr++;
    140 	}
    141 }
    142 
    143 void
    144 kasan_early_init(void *stack)
    145 {
    146 	kasan_md_early_init(stack);
    147 }
    148 
    149 void
    150 kasan_init(void)
    151 {
    152 	/* MD initialization. */
    153 	kasan_md_init();
    154 
    155 	/* Now officially enabled. */
    156 	kasan_enabled = true;
    157 
    158 	/* Call the ASAN constructors. */
    159 	kasan_ctors();
    160 }
    161 
    162 static inline const char *
    163 kasan_code_name(uint8_t code)
    164 {
    165 	switch (code) {
    166 	case KASAN_GENERIC_REDZONE:
    167 		return "GenericRedZone";
    168 	case KASAN_MALLOC_REDZONE:
    169 		return "MallocRedZone";
    170 	case KASAN_KMEM_REDZONE:
    171 		return "KmemRedZone";
    172 	case KASAN_POOL_REDZONE:
    173 		return "PoolRedZone";
    174 	case KASAN_POOL_FREED:
    175 		return "PoolUseAfterFree";
    176 	case 1 ... 7:
    177 		return "RedZonePartial";
    178 	case KASAN_STACK_LEFT:
    179 		return "StackLeft";
    180 	case KASAN_STACK_MID:
    181 		return "StackMiddle";
    182 	case KASAN_STACK_RIGHT:
    183 		return "StackRight";
    184 	case KASAN_USE_AFTER_RET:
    185 		return "UseAfterRet";
    186 	case KASAN_USE_AFTER_SCOPE:
    187 		return "UseAfterScope";
    188 	default:
    189 		return "Unknown";
    190 	}
    191 }
    192 
    193 static void
    194 kasan_report(unsigned long addr, size_t size, bool write, unsigned long pc,
    195     uint8_t code)
    196 {
    197 	REPORT("ASan: Unauthorized Access In %p: Addr %p [%zu byte%s, %s,"
    198 	    " %s]\n",
    199 	    (void *)pc, (void *)addr, size, (size > 1 ? "s" : ""),
    200 	    (write ? "write" : "read"), kasan_code_name(code));
    201 	kasan_md_unwind();
    202 }
    203 
    204 static __always_inline void
    205 kasan_shadow_1byte_markvalid(unsigned long addr)
    206 {
    207 	int8_t *byte = kasan_md_addr_to_shad((void *)addr);
    208 	int8_t last = (addr & KASAN_SHADOW_MASK) + 1;
    209 
    210 	*byte = last;
    211 }
    212 
    213 static __always_inline void
    214 kasan_shadow_Nbyte_markvalid(const void *addr, size_t size)
    215 {
    216 	size_t i;
    217 
    218 	for (i = 0; i < size; i++) {
    219 		kasan_shadow_1byte_markvalid((unsigned long)addr+i);
    220 	}
    221 }
    222 
    223 static __always_inline void
    224 kasan_shadow_Nbyte_fill(const void *addr, size_t size, uint8_t code)
    225 {
    226 	void *shad;
    227 
    228 	if (__predict_false(size == 0))
    229 		return;
    230 	if (__predict_false(kasan_md_unsupported((vaddr_t)addr)))
    231 		return;
    232 
    233 	KASSERT((vaddr_t)addr % KASAN_SHADOW_SCALE_SIZE == 0);
    234 	KASSERT(size % KASAN_SHADOW_SCALE_SIZE == 0);
    235 
    236 	shad = (void *)kasan_md_addr_to_shad(addr);
    237 	size = size >> KASAN_SHADOW_SCALE_SHIFT;
    238 
    239 	__builtin_memset(shad, code, size);
    240 }
    241 
    242 void
    243 kasan_add_redzone(size_t *size)
    244 {
    245 	*size = roundup(*size, KASAN_SHADOW_SCALE_SIZE);
    246 	*size += KASAN_SHADOW_SCALE_SIZE;
    247 }
    248 
    249 void
    250 kasan_softint(struct lwp *l)
    251 {
    252 	const void *stk = (const void *)uvm_lwp_getuarea(l);
    253 
    254 	kasan_shadow_Nbyte_fill(stk, USPACE, 0);
    255 }
    256 
    257 /*
    258  * In an area of size 'sz_with_redz', mark the 'size' first bytes as valid,
    259  * and the rest as invalid. There are generally two use cases:
    260  *
    261  *  o kasan_mark(addr, origsize, size, code), with origsize < size. This marks
    262  *    the redzone at the end of the buffer as invalid.
    263  *
    264  *  o kasan_mark(addr, size, size, 0). This marks the entire buffer as valid.
    265  */
    266 void
    267 kasan_mark(const void *addr, size_t size, size_t sz_with_redz, uint8_t code)
    268 {
    269 	size_t i, n, redz;
    270 	int8_t *shad;
    271 
    272 	KASSERT((vaddr_t)addr % KASAN_SHADOW_SCALE_SIZE == 0);
    273 	redz = sz_with_redz - roundup(size, KASAN_SHADOW_SCALE_SIZE);
    274 	KASSERT(redz % KASAN_SHADOW_SCALE_SIZE == 0);
    275 	shad = kasan_md_addr_to_shad(addr);
    276 
    277 	/* Chunks of 8 bytes, valid. */
    278 	n = size / KASAN_SHADOW_SCALE_SIZE;
    279 	for (i = 0; i < n; i++) {
    280 		*shad++ = 0;
    281 	}
    282 
    283 	/* Possibly one chunk, mid. */
    284 	if ((size & KASAN_SHADOW_MASK) != 0) {
    285 		*shad++ = (size & KASAN_SHADOW_MASK);
    286 	}
    287 
    288 	/* Chunks of 8 bytes, invalid. */
    289 	n = redz / KASAN_SHADOW_SCALE_SIZE;
    290 	for (i = 0; i < n; i++) {
    291 		*shad++ = code;
    292 	}
    293 }
    294 
    295 /* -------------------------------------------------------------------------- */
    296 
    297 #define ADDR_CROSSES_SCALE_BOUNDARY(addr, size) 		\
    298 	(addr >> KASAN_SHADOW_SCALE_SHIFT) !=			\
    299 	    ((addr + size - 1) >> KASAN_SHADOW_SCALE_SHIFT)
    300 
    301 static __always_inline bool
    302 kasan_shadow_1byte_isvalid(unsigned long addr, uint8_t *code)
    303 {
    304 	int8_t *byte = kasan_md_addr_to_shad((void *)addr);
    305 	int8_t last = (addr & KASAN_SHADOW_MASK) + 1;
    306 
    307 	if (__predict_true(*byte == 0 || last <= *byte)) {
    308 		return true;
    309 	}
    310 	*code = *byte;
    311 	return false;
    312 }
    313 
    314 static __always_inline bool
    315 kasan_shadow_2byte_isvalid(unsigned long addr, uint8_t *code)
    316 {
    317 	int8_t *byte, last;
    318 
    319 	if (ADDR_CROSSES_SCALE_BOUNDARY(addr, 2)) {
    320 		return (kasan_shadow_1byte_isvalid(addr, code) &&
    321 		    kasan_shadow_1byte_isvalid(addr+1, code));
    322 	}
    323 
    324 	byte = kasan_md_addr_to_shad((void *)addr);
    325 	last = ((addr + 1) & KASAN_SHADOW_MASK) + 1;
    326 
    327 	if (__predict_true(*byte == 0 || last <= *byte)) {
    328 		return true;
    329 	}
    330 	*code = *byte;
    331 	return false;
    332 }
    333 
    334 static __always_inline bool
    335 kasan_shadow_4byte_isvalid(unsigned long addr, uint8_t *code)
    336 {
    337 	int8_t *byte, last;
    338 
    339 	if (ADDR_CROSSES_SCALE_BOUNDARY(addr, 4)) {
    340 		return (kasan_shadow_2byte_isvalid(addr, code) &&
    341 		    kasan_shadow_2byte_isvalid(addr+2, code));
    342 	}
    343 
    344 	byte = kasan_md_addr_to_shad((void *)addr);
    345 	last = ((addr + 3) & KASAN_SHADOW_MASK) + 1;
    346 
    347 	if (__predict_true(*byte == 0 || last <= *byte)) {
    348 		return true;
    349 	}
    350 	*code = *byte;
    351 	return false;
    352 }
    353 
    354 static __always_inline bool
    355 kasan_shadow_8byte_isvalid(unsigned long addr, uint8_t *code)
    356 {
    357 	int8_t *byte, last;
    358 
    359 	if (ADDR_CROSSES_SCALE_BOUNDARY(addr, 8)) {
    360 		return (kasan_shadow_4byte_isvalid(addr, code) &&
    361 		    kasan_shadow_4byte_isvalid(addr+4, code));
    362 	}
    363 
    364 	byte = kasan_md_addr_to_shad((void *)addr);
    365 	last = ((addr + 7) & KASAN_SHADOW_MASK) + 1;
    366 
    367 	if (__predict_true(*byte == 0 || last <= *byte)) {
    368 		return true;
    369 	}
    370 	*code = *byte;
    371 	return false;
    372 }
    373 
    374 static __always_inline bool
    375 kasan_shadow_Nbyte_isvalid(unsigned long addr, size_t size, uint8_t *code)
    376 {
    377 	size_t i;
    378 
    379 	for (i = 0; i < size; i++) {
    380 		if (!kasan_shadow_1byte_isvalid(addr+i, code))
    381 			return false;
    382 	}
    383 
    384 	return true;
    385 }
    386 
    387 static __always_inline void
    388 kasan_shadow_check(unsigned long addr, size_t size, bool write,
    389     unsigned long retaddr)
    390 {
    391 	uint8_t code;
    392 	bool valid;
    393 
    394 	if (__predict_false(!kasan_enabled))
    395 		return;
    396 	if (__predict_false(size == 0))
    397 		return;
    398 	if (__predict_false(kasan_md_unsupported(addr)))
    399 		return;
    400 
    401 	if (__builtin_constant_p(size)) {
    402 		switch (size) {
    403 		case 1:
    404 			valid = kasan_shadow_1byte_isvalid(addr, &code);
    405 			break;
    406 		case 2:
    407 			valid = kasan_shadow_2byte_isvalid(addr, &code);
    408 			break;
    409 		case 4:
    410 			valid = kasan_shadow_4byte_isvalid(addr, &code);
    411 			break;
    412 		case 8:
    413 			valid = kasan_shadow_8byte_isvalid(addr, &code);
    414 			break;
    415 		default:
    416 			valid = kasan_shadow_Nbyte_isvalid(addr, size, &code);
    417 			break;
    418 		}
    419 	} else {
    420 		valid = kasan_shadow_Nbyte_isvalid(addr, size, &code);
    421 	}
    422 
    423 	if (__predict_false(!valid)) {
    424 		kasan_report(addr, size, write, retaddr, code);
    425 	}
    426 }
    427 
    428 /* -------------------------------------------------------------------------- */
    429 
    430 void *
    431 kasan_memcpy(void *dst, const void *src, size_t len)
    432 {
    433 	kasan_shadow_check((unsigned long)src, len, false, __RET_ADDR);
    434 	kasan_shadow_check((unsigned long)dst, len, true, __RET_ADDR);
    435 	return __builtin_memcpy(dst, src, len);
    436 }
    437 
    438 int
    439 kasan_memcmp(const void *b1, const void *b2, size_t len)
    440 {
    441 	kasan_shadow_check((unsigned long)b1, len, false, __RET_ADDR);
    442 	kasan_shadow_check((unsigned long)b2, len, false, __RET_ADDR);
    443 	return __builtin_memcmp(b1, b2, len);
    444 }
    445 
    446 void *
    447 kasan_memset(void *b, int c, size_t len)
    448 {
    449 	kasan_shadow_check((unsigned long)b, len, true, __RET_ADDR);
    450 	return __builtin_memset(b, c, len);
    451 }
    452 
    453 void *
    454 kasan_memmove(void *dst, const void *src, size_t len)
    455 {
    456 	kasan_shadow_check((unsigned long)src, len, false, __RET_ADDR);
    457 	kasan_shadow_check((unsigned long)dst, len, true, __RET_ADDR);
    458 	return __builtin_memmove(dst, src, len);
    459 }
    460 
    461 char *
    462 kasan_strcpy(char *dst, const char *src)
    463 {
    464 	char *save = dst;
    465 
    466 	while (1) {
    467 		kasan_shadow_check((unsigned long)src, 1, false, __RET_ADDR);
    468 		kasan_shadow_check((unsigned long)dst, 1, true, __RET_ADDR);
    469 		*dst = *src;
    470 		if (*src == '\0')
    471 			break;
    472 		src++, dst++;
    473 	}
    474 
    475 	return save;
    476 }
    477 
    478 int
    479 kasan_strcmp(const char *s1, const char *s2)
    480 {
    481 	while (1) {
    482 		kasan_shadow_check((unsigned long)s1, 1, false, __RET_ADDR);
    483 		kasan_shadow_check((unsigned long)s2, 1, false, __RET_ADDR);
    484 		if (*s1 != *s2)
    485 			break;
    486 		if (*s1 == '\0')
    487 			return 0;
    488 		s1++, s2++;
    489 	}
    490 
    491 	return (*(const unsigned char *)s1 - *(const unsigned char *)s2);
    492 }
    493 
    494 size_t
    495 kasan_strlen(const char *str)
    496 {
    497 	const char *s;
    498 
    499 	s = str;
    500 	while (1) {
    501 		kasan_shadow_check((unsigned long)s, 1, false, __RET_ADDR);
    502 		if (*s == '\0')
    503 			break;
    504 		s++;
    505 	}
    506 
    507 	return (s - str);
    508 }
    509 
    510 char *
    511 kasan_strcat(char *dst, const char *src)
    512 {
    513 	size_t ldst, lsrc;
    514 
    515 	ldst = __builtin_strlen(dst);
    516 	lsrc = __builtin_strlen(src);
    517 	kasan_shadow_check((unsigned long)dst, ldst + lsrc + 1, true,
    518 	    __RET_ADDR);
    519 	kasan_shadow_check((unsigned long)src, lsrc + 1, false,
    520 	    __RET_ADDR);
    521 
    522 	return __builtin_strcat(dst, src);
    523 }
    524 
    525 char *
    526 kasan_strchr(const char *s, int c)
    527 {
    528 	kasan_shadow_check((unsigned long)s, __builtin_strlen(s) + 1, false,
    529 	    __RET_ADDR);
    530 	return __builtin_strchr(s, c);
    531 }
    532 
    533 char *
    534 kasan_strrchr(const char *s, int c)
    535 {
    536 	kasan_shadow_check((unsigned long)s, __builtin_strlen(s) + 1, false,
    537 	    __RET_ADDR);
    538 	return __builtin_strrchr(s, c);
    539 }
    540 
    541 #undef kcopy
    542 #undef copystr
    543 #undef copyinstr
    544 #undef copyoutstr
    545 #undef copyin
    546 
    547 int	kasan_kcopy(const void *, void *, size_t);
    548 int	kasan_copystr(const void *, void *, size_t, size_t *);
    549 int	kasan_copyinstr(const void *, void *, size_t, size_t *);
    550 int	kasan_copyoutstr(const void *, void *, size_t, size_t *);
    551 int	kasan_copyin(const void *, void *, size_t);
    552 int	kcopy(const void *, void *, size_t);
    553 int	copystr(const void *, void *, size_t, size_t *);
    554 int	copyinstr(const void *, void *, size_t, size_t *);
    555 int	copyoutstr(const void *, void *, size_t, size_t *);
    556 int	copyin(const void *, void *, size_t);
    557 
    558 int
    559 kasan_kcopy(const void *src, void *dst, size_t len)
    560 {
    561 	kasan_shadow_check((unsigned long)src, len, false, __RET_ADDR);
    562 	kasan_shadow_check((unsigned long)dst, len, true, __RET_ADDR);
    563 	return kcopy(src, dst, len);
    564 }
    565 
    566 int
    567 kasan_copystr(const void *kfaddr, void *kdaddr, size_t len, size_t *done)
    568 {
    569 	kasan_shadow_check((unsigned long)kdaddr, len, true, __RET_ADDR);
    570 	return copystr(kfaddr, kdaddr, len, done);
    571 }
    572 
    573 int
    574 kasan_copyin(const void *uaddr, void *kaddr, size_t len)
    575 {
    576 	kasan_shadow_check((unsigned long)kaddr, len, true, __RET_ADDR);
    577 	return copyin(uaddr, kaddr, len);
    578 }
    579 
    580 int
    581 kasan_copyinstr(const void *uaddr, void *kaddr, size_t len, size_t *done)
    582 {
    583 	kasan_shadow_check((unsigned long)kaddr, len, true, __RET_ADDR);
    584 	return copyinstr(uaddr, kaddr, len, done);
    585 }
    586 
    587 int
    588 kasan_copyoutstr(const void *kaddr, void *uaddr, size_t len, size_t *done)
    589 {
    590 	kasan_shadow_check((unsigned long)kaddr, len, false, __RET_ADDR);
    591 	return copyoutstr(kaddr, uaddr, len, done);
    592 }
    593 
    594 /* -------------------------------------------------------------------------- */
    595 
    596 #undef _ucas_32
    597 #undef _ucas_32_mp
    598 #undef _ucas_64
    599 #undef _ucas_64_mp
    600 #undef _ufetch_8
    601 #undef _ufetch_16
    602 #undef _ufetch_32
    603 #undef _ufetch_64
    604 
    605 int _ucas_32(volatile uint32_t *, uint32_t, uint32_t, uint32_t *);
    606 int kasan__ucas_32(volatile uint32_t *, uint32_t, uint32_t, uint32_t *);
    607 int
    608 kasan__ucas_32(volatile uint32_t *uaddr, uint32_t old, uint32_t new,
    609     uint32_t *ret)
    610 {
    611 	kasan_shadow_check((unsigned long)ret, sizeof(*ret), true,
    612 	    __RET_ADDR);
    613 	return _ucas_32(uaddr, old, new, ret);
    614 }
    615 
    616 #ifdef __HAVE_UCAS_MP
    617 int _ucas_32_mp(volatile uint32_t *, uint32_t, uint32_t, uint32_t *);
    618 int kasan__ucas_32_mp(volatile uint32_t *, uint32_t, uint32_t, uint32_t *);
    619 int
    620 kasan__ucas_32_mp(volatile uint32_t *uaddr, uint32_t old, uint32_t new,
    621     uint32_t *ret)
    622 {
    623 	kasan_shadow_check((unsigned long)ret, sizeof(*ret), true,
    624 	    __RET_ADDR);
    625 	return _ucas_32_mp(uaddr, old, new, ret);
    626 }
    627 #endif
    628 
    629 #ifdef _LP64
    630 int _ucas_64(volatile uint64_t *, uint64_t, uint64_t, uint64_t *);
    631 int kasan__ucas_64(volatile uint64_t *, uint64_t, uint64_t, uint64_t *);
    632 int
    633 kasan__ucas_64(volatile uint64_t *uaddr, uint64_t old, uint64_t new,
    634     uint64_t *ret)
    635 {
    636 	kasan_shadow_check((unsigned long)ret, sizeof(*ret), true,
    637 	    __RET_ADDR);
    638 	return _ucas_64(uaddr, old, new, ret);
    639 }
    640 
    641 #ifdef __HAVE_UCAS_MP
    642 int _ucas_64_mp(volatile uint64_t *, uint64_t, uint64_t, uint64_t *);
    643 int kasan__ucas_64_mp(volatile uint64_t *, uint64_t, uint64_t, uint64_t *);
    644 int
    645 kasan__ucas_64_mp(volatile uint64_t *uaddr, uint64_t old, uint64_t new,
    646     uint64_t *ret)
    647 {
    648 	kasan_shadow_check((unsigned long)ret, sizeof(*ret), true,
    649 	    __RET_ADDR);
    650 	return _ucas_64_mp(uaddr, old, new, ret);
    651 }
    652 #endif
    653 #endif
    654 
    655 int _ufetch_8(const uint8_t *, uint8_t *);
    656 int kasan__ufetch_8(const uint8_t *, uint8_t *);
    657 int
    658 kasan__ufetch_8(const uint8_t *uaddr, uint8_t *valp)
    659 {
    660 	kasan_shadow_check((unsigned long)valp, sizeof(*valp), true,
    661 	    __RET_ADDR);
    662 	return _ufetch_8(uaddr, valp);
    663 }
    664 
    665 int _ufetch_16(const uint16_t *, uint16_t *);
    666 int kasan__ufetch_16(const uint16_t *, uint16_t *);
    667 int
    668 kasan__ufetch_16(const uint16_t *uaddr, uint16_t *valp)
    669 {
    670 	kasan_shadow_check((unsigned long)valp, sizeof(*valp), true,
    671 	    __RET_ADDR);
    672 	return _ufetch_16(uaddr, valp);
    673 }
    674 
    675 int _ufetch_32(const uint32_t *, uint32_t *);
    676 int kasan__ufetch_32(const uint32_t *, uint32_t *);
    677 int
    678 kasan__ufetch_32(const uint32_t *uaddr, uint32_t *valp)
    679 {
    680 	kasan_shadow_check((unsigned long)valp, sizeof(*valp), true,
    681 	    __RET_ADDR);
    682 	return _ufetch_32(uaddr, valp);
    683 }
    684 
    685 #ifdef _LP64
    686 int _ufetch_64(const uint64_t *, uint64_t *);
    687 int kasan__ufetch_64(const uint64_t *, uint64_t *);
    688 int
    689 kasan__ufetch_64(const uint64_t *uaddr, uint64_t *valp)
    690 {
    691 	kasan_shadow_check((unsigned long)valp, sizeof(*valp), true,
    692 	    __RET_ADDR);
    693 	return _ufetch_64(uaddr, valp);
    694 }
    695 #endif
    696 
    697 /* -------------------------------------------------------------------------- */
    698 
    699 #undef atomic_add_32
    700 #undef atomic_add_int
    701 #undef atomic_add_long
    702 #undef atomic_add_ptr
    703 #undef atomic_add_64
    704 #undef atomic_add_32_nv
    705 #undef atomic_add_int_nv
    706 #undef atomic_add_long_nv
    707 #undef atomic_add_ptr_nv
    708 #undef atomic_add_64_nv
    709 #undef atomic_and_32
    710 #undef atomic_and_uint
    711 #undef atomic_and_ulong
    712 #undef atomic_and_64
    713 #undef atomic_and_32_nv
    714 #undef atomic_and_uint_nv
    715 #undef atomic_and_ulong_nv
    716 #undef atomic_and_64_nv
    717 #undef atomic_or_32
    718 #undef atomic_or_uint
    719 #undef atomic_or_ulong
    720 #undef atomic_or_64
    721 #undef atomic_or_32_nv
    722 #undef atomic_or_uint_nv
    723 #undef atomic_or_ulong_nv
    724 #undef atomic_or_64_nv
    725 #undef atomic_cas_32
    726 #undef atomic_cas_uint
    727 #undef atomic_cas_ulong
    728 #undef atomic_cas_ptr
    729 #undef atomic_cas_64
    730 #undef atomic_cas_32_ni
    731 #undef atomic_cas_uint_ni
    732 #undef atomic_cas_ulong_ni
    733 #undef atomic_cas_ptr_ni
    734 #undef atomic_cas_64_ni
    735 #undef atomic_swap_32
    736 #undef atomic_swap_uint
    737 #undef atomic_swap_ulong
    738 #undef atomic_swap_ptr
    739 #undef atomic_swap_64
    740 #undef atomic_dec_32
    741 #undef atomic_dec_uint
    742 #undef atomic_dec_ulong
    743 #undef atomic_dec_ptr
    744 #undef atomic_dec_64
    745 #undef atomic_dec_32_nv
    746 #undef atomic_dec_uint_nv
    747 #undef atomic_dec_ulong_nv
    748 #undef atomic_dec_ptr_nv
    749 #undef atomic_dec_64_nv
    750 #undef atomic_inc_32
    751 #undef atomic_inc_uint
    752 #undef atomic_inc_ulong
    753 #undef atomic_inc_ptr
    754 #undef atomic_inc_64
    755 #undef atomic_inc_32_nv
    756 #undef atomic_inc_uint_nv
    757 #undef atomic_inc_ulong_nv
    758 #undef atomic_inc_ptr_nv
    759 #undef atomic_inc_64_nv
    760 
    761 #define ASAN_ATOMIC_FUNC_ADD(name, tret, targ1, targ2) \
    762 	void atomic_add_##name(volatile targ1 *, targ2); \
    763 	void kasan_atomic_add_##name(volatile targ1 *, targ2); \
    764 	void kasan_atomic_add_##name(volatile targ1 *ptr, targ2 val) \
    765 	{ \
    766 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
    767 		    __RET_ADDR); \
    768 		atomic_add_##name(ptr, val); \
    769 	} \
    770 	tret atomic_add_##name##_nv(volatile targ1 *, targ2); \
    771 	tret kasan_atomic_add_##name##_nv(volatile targ1 *, targ2); \
    772 	tret kasan_atomic_add_##name##_nv(volatile targ1 *ptr, targ2 val) \
    773 	{ \
    774 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
    775 		    __RET_ADDR); \
    776 		return atomic_add_##name##_nv(ptr, val); \
    777 	}
    778 
    779 #define ASAN_ATOMIC_FUNC_AND(name, tret, targ1, targ2) \
    780 	void atomic_and_##name(volatile targ1 *, targ2); \
    781 	void kasan_atomic_and_##name(volatile targ1 *, targ2); \
    782 	void kasan_atomic_and_##name(volatile targ1 *ptr, targ2 val) \
    783 	{ \
    784 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
    785 		    __RET_ADDR); \
    786 		atomic_and_##name(ptr, val); \
    787 	} \
    788 	tret atomic_and_##name##_nv(volatile targ1 *, targ2); \
    789 	tret kasan_atomic_and_##name##_nv(volatile targ1 *, targ2); \
    790 	tret kasan_atomic_and_##name##_nv(volatile targ1 *ptr, targ2 val) \
    791 	{ \
    792 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
    793 		    __RET_ADDR); \
    794 		return atomic_and_##name##_nv(ptr, val); \
    795 	}
    796 
    797 #define ASAN_ATOMIC_FUNC_OR(name, tret, targ1, targ2) \
    798 	void atomic_or_##name(volatile targ1 *, targ2); \
    799 	void kasan_atomic_or_##name(volatile targ1 *, targ2); \
    800 	void kasan_atomic_or_##name(volatile targ1 *ptr, targ2 val) \
    801 	{ \
    802 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
    803 		    __RET_ADDR); \
    804 		atomic_or_##name(ptr, val); \
    805 	} \
    806 	tret atomic_or_##name##_nv(volatile targ1 *, targ2); \
    807 	tret kasan_atomic_or_##name##_nv(volatile targ1 *, targ2); \
    808 	tret kasan_atomic_or_##name##_nv(volatile targ1 *ptr, targ2 val) \
    809 	{ \
    810 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
    811 		    __RET_ADDR); \
    812 		return atomic_or_##name##_nv(ptr, val); \
    813 	}
    814 
    815 #define ASAN_ATOMIC_FUNC_CAS(name, tret, targ1, targ2) \
    816 	tret atomic_cas_##name(volatile targ1 *, targ2, targ2); \
    817 	tret kasan_atomic_cas_##name(volatile targ1 *, targ2, targ2); \
    818 	tret kasan_atomic_cas_##name(volatile targ1 *ptr, targ2 exp, targ2 new) \
    819 	{ \
    820 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
    821 		    __RET_ADDR); \
    822 		return atomic_cas_##name(ptr, exp, new); \
    823 	} \
    824 	tret atomic_cas_##name##_ni(volatile targ1 *, targ2, targ2); \
    825 	tret kasan_atomic_cas_##name##_ni(volatile targ1 *, targ2, targ2); \
    826 	tret kasan_atomic_cas_##name##_ni(volatile targ1 *ptr, targ2 exp, targ2 new) \
    827 	{ \
    828 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
    829 		    __RET_ADDR); \
    830 		return atomic_cas_##name##_ni(ptr, exp, new); \
    831 	}
    832 
    833 #define ASAN_ATOMIC_FUNC_SWAP(name, tret, targ1, targ2) \
    834 	tret atomic_swap_##name(volatile targ1 *, targ2); \
    835 	tret kasan_atomic_swap_##name(volatile targ1 *, targ2); \
    836 	tret kasan_atomic_swap_##name(volatile targ1 *ptr, targ2 val) \
    837 	{ \
    838 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
    839 		    __RET_ADDR); \
    840 		return atomic_swap_##name(ptr, val); \
    841 	}
    842 
    843 #define ASAN_ATOMIC_FUNC_DEC(name, tret, targ1) \
    844 	void atomic_dec_##name(volatile targ1 *); \
    845 	void kasan_atomic_dec_##name(volatile targ1 *); \
    846 	void kasan_atomic_dec_##name(volatile targ1 *ptr) \
    847 	{ \
    848 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
    849 		    __RET_ADDR); \
    850 		atomic_dec_##name(ptr); \
    851 	} \
    852 	tret atomic_dec_##name##_nv(volatile targ1 *); \
    853 	tret kasan_atomic_dec_##name##_nv(volatile targ1 *); \
    854 	tret kasan_atomic_dec_##name##_nv(volatile targ1 *ptr) \
    855 	{ \
    856 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
    857 		    __RET_ADDR); \
    858 		return atomic_dec_##name##_nv(ptr); \
    859 	}
    860 
    861 #define ASAN_ATOMIC_FUNC_INC(name, tret, targ1) \
    862 	void atomic_inc_##name(volatile targ1 *); \
    863 	void kasan_atomic_inc_##name(volatile targ1 *); \
    864 	void kasan_atomic_inc_##name(volatile targ1 *ptr) \
    865 	{ \
    866 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
    867 		    __RET_ADDR); \
    868 		atomic_inc_##name(ptr); \
    869 	} \
    870 	tret atomic_inc_##name##_nv(volatile targ1 *); \
    871 	tret kasan_atomic_inc_##name##_nv(volatile targ1 *); \
    872 	tret kasan_atomic_inc_##name##_nv(volatile targ1 *ptr) \
    873 	{ \
    874 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
    875 		    __RET_ADDR); \
    876 		return atomic_inc_##name##_nv(ptr); \
    877 	}
    878 
    879 ASAN_ATOMIC_FUNC_ADD(32, uint32_t, uint32_t, int32_t);
    880 ASAN_ATOMIC_FUNC_ADD(64, uint64_t, uint64_t, int64_t);
    881 ASAN_ATOMIC_FUNC_ADD(int, unsigned int, unsigned int, int);
    882 ASAN_ATOMIC_FUNC_ADD(long, unsigned long, unsigned long, long);
    883 ASAN_ATOMIC_FUNC_ADD(ptr, void *, void, ssize_t);
    884 
    885 ASAN_ATOMIC_FUNC_AND(32, uint32_t, uint32_t, uint32_t);
    886 ASAN_ATOMIC_FUNC_AND(64, uint64_t, uint64_t, uint64_t);
    887 ASAN_ATOMIC_FUNC_AND(uint, unsigned int, unsigned int, unsigned int);
    888 ASAN_ATOMIC_FUNC_AND(ulong, unsigned long, unsigned long, unsigned long);
    889 
    890 ASAN_ATOMIC_FUNC_OR(32, uint32_t, uint32_t, uint32_t);
    891 ASAN_ATOMIC_FUNC_OR(64, uint64_t, uint64_t, uint64_t);
    892 ASAN_ATOMIC_FUNC_OR(uint, unsigned int, unsigned int, unsigned int);
    893 ASAN_ATOMIC_FUNC_OR(ulong, unsigned long, unsigned long, unsigned long);
    894 
    895 ASAN_ATOMIC_FUNC_CAS(32, uint32_t, uint32_t, uint32_t);
    896 ASAN_ATOMIC_FUNC_CAS(64, uint64_t, uint64_t, uint64_t);
    897 ASAN_ATOMIC_FUNC_CAS(uint, unsigned int, unsigned int, unsigned int);
    898 ASAN_ATOMIC_FUNC_CAS(ulong, unsigned long, unsigned long, unsigned long);
    899 ASAN_ATOMIC_FUNC_CAS(ptr, void *, void, void *);
    900 
    901 ASAN_ATOMIC_FUNC_SWAP(32, uint32_t, uint32_t, uint32_t);
    902 ASAN_ATOMIC_FUNC_SWAP(64, uint64_t, uint64_t, uint64_t);
    903 ASAN_ATOMIC_FUNC_SWAP(uint, unsigned int, unsigned int, unsigned int);
    904 ASAN_ATOMIC_FUNC_SWAP(ulong, unsigned long, unsigned long, unsigned long);
    905 ASAN_ATOMIC_FUNC_SWAP(ptr, void *, void, void *);
    906 
    907 ASAN_ATOMIC_FUNC_DEC(32, uint32_t, uint32_t)
    908 ASAN_ATOMIC_FUNC_DEC(64, uint64_t, uint64_t)
    909 ASAN_ATOMIC_FUNC_DEC(uint, unsigned int, unsigned int);
    910 ASAN_ATOMIC_FUNC_DEC(ulong, unsigned long, unsigned long);
    911 ASAN_ATOMIC_FUNC_DEC(ptr, void *, void);
    912 
    913 ASAN_ATOMIC_FUNC_INC(32, uint32_t, uint32_t)
    914 ASAN_ATOMIC_FUNC_INC(64, uint64_t, uint64_t)
    915 ASAN_ATOMIC_FUNC_INC(uint, unsigned int, unsigned int);
    916 ASAN_ATOMIC_FUNC_INC(ulong, unsigned long, unsigned long);
    917 ASAN_ATOMIC_FUNC_INC(ptr, void *, void);
    918 
    919 /* -------------------------------------------------------------------------- */
    920 
    921 #ifdef __HAVE_KASAN_INSTR_BUS
    922 
    923 #include <sys/bus.h>
    924 
    925 #undef bus_space_read_multi_1
    926 #undef bus_space_read_multi_2
    927 #undef bus_space_read_multi_4
    928 #undef bus_space_read_multi_8
    929 #undef bus_space_read_multi_stream_1
    930 #undef bus_space_read_multi_stream_2
    931 #undef bus_space_read_multi_stream_4
    932 #undef bus_space_read_multi_stream_8
    933 #undef bus_space_read_region_1
    934 #undef bus_space_read_region_2
    935 #undef bus_space_read_region_4
    936 #undef bus_space_read_region_8
    937 #undef bus_space_read_region_stream_1
    938 #undef bus_space_read_region_stream_2
    939 #undef bus_space_read_region_stream_4
    940 #undef bus_space_read_region_stream_8
    941 #undef bus_space_write_multi_1
    942 #undef bus_space_write_multi_2
    943 #undef bus_space_write_multi_4
    944 #undef bus_space_write_multi_8
    945 #undef bus_space_write_multi_stream_1
    946 #undef bus_space_write_multi_stream_2
    947 #undef bus_space_write_multi_stream_4
    948 #undef bus_space_write_multi_stream_8
    949 #undef bus_space_write_region_1
    950 #undef bus_space_write_region_2
    951 #undef bus_space_write_region_4
    952 #undef bus_space_write_region_8
    953 #undef bus_space_write_region_stream_1
    954 #undef bus_space_write_region_stream_2
    955 #undef bus_space_write_region_stream_4
    956 #undef bus_space_write_region_stream_8
    957 
    958 #define ASAN_BUS_READ_FUNC(bytes, bits) \
    959 	void bus_space_read_multi_##bytes(bus_space_tag_t, bus_space_handle_t,	\
    960 	    bus_size_t, uint##bits##_t *, bus_size_t);				\
    961 	void kasan_bus_space_read_multi_##bytes(bus_space_tag_t,		\
    962 	    bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t);	\
    963 	void kasan_bus_space_read_multi_##bytes(bus_space_tag_t tag,		\
    964 	    bus_space_handle_t hnd, bus_size_t size, uint##bits##_t *buf,	\
    965 	    bus_size_t count)							\
    966 	{									\
    967 		kasan_shadow_check((uintptr_t)buf,				\
    968 		    sizeof(uint##bits##_t) * count, false, __RET_ADDR);		\
    969 		bus_space_read_multi_##bytes(tag, hnd, size, buf, count);	\
    970 	}									\
    971 	void bus_space_read_multi_stream_##bytes(bus_space_tag_t,		\
    972 	    bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t);	\
    973 	void kasan_bus_space_read_multi_stream_##bytes(bus_space_tag_t,		\
    974 	    bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t);	\
    975 	void kasan_bus_space_read_multi_stream_##bytes(bus_space_tag_t tag,	\
    976 	    bus_space_handle_t hnd, bus_size_t size, uint##bits##_t *buf,	\
    977 	    bus_size_t count)							\
    978 	{									\
    979 		kasan_shadow_check((uintptr_t)buf,				\
    980 		    sizeof(uint##bits##_t) * count, false, __RET_ADDR);		\
    981 		bus_space_read_multi_stream_##bytes(tag, hnd, size, buf, count);\
    982 	}									\
    983 	void bus_space_read_region_##bytes(bus_space_tag_t, bus_space_handle_t,	\
    984 	    bus_size_t, uint##bits##_t *, bus_size_t);				\
    985 	void kasan_bus_space_read_region_##bytes(bus_space_tag_t,		\
    986 	    bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t);	\
    987 	void kasan_bus_space_read_region_##bytes(bus_space_tag_t tag,		\
    988 	    bus_space_handle_t hnd, bus_size_t size, uint##bits##_t *buf,	\
    989 	    bus_size_t count)							\
    990 	{									\
    991 		kasan_shadow_check((uintptr_t)buf,				\
    992 		    sizeof(uint##bits##_t) * count, false, __RET_ADDR);		\
    993 		bus_space_read_region_##bytes(tag, hnd, size, buf, count);	\
    994 	}									\
    995 	void bus_space_read_region_stream_##bytes(bus_space_tag_t,		\
    996 	    bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t);	\
    997 	void kasan_bus_space_read_region_stream_##bytes(bus_space_tag_t,	\
    998 	    bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t);	\
    999 	void kasan_bus_space_read_region_stream_##bytes(bus_space_tag_t tag,	\
   1000 	    bus_space_handle_t hnd, bus_size_t size, uint##bits##_t *buf,	\
   1001 	    bus_size_t count)							\
   1002 	{									\
   1003 		kasan_shadow_check((uintptr_t)buf,				\
   1004 		    sizeof(uint##bits##_t) * count, false, __RET_ADDR);		\
   1005 		bus_space_read_region_stream_##bytes(tag, hnd, size, buf, count);\
   1006 	}
   1007 
   1008 #define ASAN_BUS_WRITE_FUNC(bytes, bits) \
   1009 	void bus_space_write_multi_##bytes(bus_space_tag_t, bus_space_handle_t,	\
   1010 	    bus_size_t, const uint##bits##_t *, bus_size_t);			\
   1011 	void kasan_bus_space_write_multi_##bytes(bus_space_tag_t,		\
   1012 	    bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
   1013 	void kasan_bus_space_write_multi_##bytes(bus_space_tag_t tag,		\
   1014 	    bus_space_handle_t hnd, bus_size_t size, const uint##bits##_t *buf,	\
   1015 	    bus_size_t count)							\
   1016 	{									\
   1017 		kasan_shadow_check((uintptr_t)buf,				\
   1018 		    sizeof(uint##bits##_t) * count, true, __RET_ADDR);		\
   1019 		bus_space_write_multi_##bytes(tag, hnd, size, buf, count);	\
   1020 	}									\
   1021 	void bus_space_write_multi_stream_##bytes(bus_space_tag_t,		\
   1022 	    bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
   1023 	void kasan_bus_space_write_multi_stream_##bytes(bus_space_tag_t,	\
   1024 	    bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
   1025 	void kasan_bus_space_write_multi_stream_##bytes(bus_space_tag_t tag,	\
   1026 	    bus_space_handle_t hnd, bus_size_t size, const uint##bits##_t *buf,	\
   1027 	    bus_size_t count)							\
   1028 	{									\
   1029 		kasan_shadow_check((uintptr_t)buf,				\
   1030 		    sizeof(uint##bits##_t) * count, true, __RET_ADDR);		\
   1031 		bus_space_write_multi_stream_##bytes(tag, hnd, size, buf, count);\
   1032 	}									\
   1033 	void bus_space_write_region_##bytes(bus_space_tag_t, bus_space_handle_t,\
   1034 	    bus_size_t, const uint##bits##_t *, bus_size_t);			\
   1035 	void kasan_bus_space_write_region_##bytes(bus_space_tag_t,		\
   1036 	    bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
   1037 	void kasan_bus_space_write_region_##bytes(bus_space_tag_t tag,		\
   1038 	    bus_space_handle_t hnd, bus_size_t size, const uint##bits##_t *buf,	\
   1039 	    bus_size_t count)							\
   1040 	{									\
   1041 		kasan_shadow_check((uintptr_t)buf,				\
   1042 		    sizeof(uint##bits##_t) * count, true, __RET_ADDR);		\
   1043 		bus_space_write_region_##bytes(tag, hnd, size, buf, count);	\
   1044 	}									\
   1045 	void bus_space_write_region_stream_##bytes(bus_space_tag_t,		\
   1046 	    bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
   1047 	void kasan_bus_space_write_region_stream_##bytes(bus_space_tag_t,	\
   1048 	    bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
   1049 	void kasan_bus_space_write_region_stream_##bytes(bus_space_tag_t tag,	\
   1050 	    bus_space_handle_t hnd, bus_size_t size, const uint##bits##_t *buf,	\
   1051 	    bus_size_t count)							\
   1052 	{									\
   1053 		kasan_shadow_check((uintptr_t)buf,				\
   1054 		    sizeof(uint##bits##_t) * count, true, __RET_ADDR);		\
   1055 		bus_space_write_region_stream_##bytes(tag, hnd, size, buf, count);\
   1056 	}
   1057 
   1058 ASAN_BUS_READ_FUNC(1, 8)
   1059 ASAN_BUS_READ_FUNC(2, 16)
   1060 ASAN_BUS_READ_FUNC(4, 32)
   1061 ASAN_BUS_READ_FUNC(8, 64)
   1062 
   1063 ASAN_BUS_WRITE_FUNC(1, 8)
   1064 ASAN_BUS_WRITE_FUNC(2, 16)
   1065 ASAN_BUS_WRITE_FUNC(4, 32)
   1066 ASAN_BUS_WRITE_FUNC(8, 64)
   1067 
   1068 #endif /* __HAVE_KASAN_INSTR_BUS */
   1069 
   1070 /* -------------------------------------------------------------------------- */
   1071 
   1072 #ifdef __HAVE_KASAN_INSTR_DMA
   1073 
   1074 #include <sys/mbuf.h>
   1075 
   1076 static void
   1077 kasan_dma_sync_linear(uint8_t *buf, bus_addr_t offset, bus_size_t len,
   1078     bool write, uintptr_t pc)
   1079 {
   1080 	kasan_shadow_check((uintptr_t)(buf + offset), len, write, pc);
   1081 }
   1082 
   1083 static void
   1084 kasan_dma_sync_mbuf(struct mbuf *m, bus_addr_t offset, bus_size_t len,
   1085     bool write, uintptr_t pc)
   1086 {
   1087 	bus_addr_t minlen;
   1088 
   1089 	for (; m != NULL && len != 0; m = m->m_next) {
   1090 		kasan_shadow_check((uintptr_t)m, sizeof(*m), false, pc);
   1091 
   1092 		if (offset >= m->m_len) {
   1093 			offset -= m->m_len;
   1094 			continue;
   1095 		}
   1096 
   1097 		minlen = MIN(len, m->m_len - offset);
   1098 		kasan_shadow_check((uintptr_t)(mtod(m, char *) + offset),
   1099 		    minlen, write, pc);
   1100 
   1101 		offset = 0;
   1102 		len -= minlen;
   1103 	}
   1104 }
   1105 
   1106 static void
   1107 kasan_dma_sync_uio(struct uio *uio, bus_addr_t offset, bus_size_t len,
   1108     bool write, uintptr_t pc)
   1109 {
   1110 	bus_size_t minlen, resid;
   1111 	struct iovec *iov;
   1112 	int i;
   1113 
   1114 	kasan_shadow_check((uintptr_t)uio, sizeof(struct uio), false, pc);
   1115 
   1116 	if (!VMSPACE_IS_KERNEL_P(uio->uio_vmspace))
   1117 		return;
   1118 
   1119 	resid = uio->uio_resid;
   1120 	iov = uio->uio_iov;
   1121 
   1122 	for (i = 0; i < uio->uio_iovcnt && resid != 0; i++) {
   1123 		kasan_shadow_check((uintptr_t)&iov[i], sizeof(iov[i]),
   1124 		    false, pc);
   1125 		minlen = MIN(resid, iov[i].iov_len);
   1126 		kasan_shadow_check((uintptr_t)iov[i].iov_base, minlen,
   1127 		    write, pc);
   1128 		resid -= minlen;
   1129 	}
   1130 }
   1131 
   1132 void
   1133 kasan_dma_sync(bus_dmamap_t map, bus_addr_t offset, bus_size_t len, int ops)
   1134 {
   1135 	bool write = (ops & (BUS_DMASYNC_PREWRITE|BUS_DMASYNC_POSTWRITE)) != 0;
   1136 
   1137 	switch (map->dm_buftype) {
   1138 	case KASAN_DMA_LINEAR:
   1139 		kasan_dma_sync_linear(map->dm_buf, offset, len, write,
   1140 		    __RET_ADDR);
   1141 		break;
   1142 	case KASAN_DMA_MBUF:
   1143 		kasan_dma_sync_mbuf(map->dm_buf, offset, len, write,
   1144 		    __RET_ADDR);
   1145 		break;
   1146 	case KASAN_DMA_UIO:
   1147 		kasan_dma_sync_uio(map->dm_buf, offset, len, write,
   1148 		    __RET_ADDR);
   1149 		break;
   1150 	case KASAN_DMA_RAW:
   1151 		break;
   1152 	default:
   1153 		panic("%s: impossible", __func__);
   1154 	}
   1155 }
   1156 
   1157 void
   1158 kasan_dma_load(bus_dmamap_t map, void *buf, bus_size_t buflen, int type)
   1159 {
   1160 	map->dm_buf = buf;
   1161 	map->dm_buflen = buflen;
   1162 	map->dm_buftype = type;
   1163 }
   1164 
   1165 #endif /* __HAVE_KASAN_INSTR_DMA */
   1166 
   1167 /* -------------------------------------------------------------------------- */
   1168 
   1169 void __asan_register_globals(struct __asan_global *, size_t);
   1170 void __asan_unregister_globals(struct __asan_global *, size_t);
   1171 
   1172 void
   1173 __asan_register_globals(struct __asan_global *globals, size_t n)
   1174 {
   1175 	size_t i;
   1176 
   1177 	for (i = 0; i < n; i++) {
   1178 		kasan_mark(globals[i].beg, globals[i].size,
   1179 		    globals[i].size_with_redzone, KASAN_GENERIC_REDZONE);
   1180 	}
   1181 }
   1182 
   1183 void
   1184 __asan_unregister_globals(struct __asan_global *globals, size_t n)
   1185 {
   1186 	/* never called */
   1187 }
   1188 
   1189 #define ASAN_LOAD_STORE(size)					\
   1190 	void __asan_load##size(unsigned long);			\
   1191 	void __asan_load##size(unsigned long addr)		\
   1192 	{							\
   1193 		kasan_shadow_check(addr, size, false, __RET_ADDR);\
   1194 	} 							\
   1195 	void __asan_load##size##_noabort(unsigned long);	\
   1196 	void __asan_load##size##_noabort(unsigned long addr)	\
   1197 	{							\
   1198 		kasan_shadow_check(addr, size, false, __RET_ADDR);\
   1199 	}							\
   1200 	void __asan_store##size(unsigned long);			\
   1201 	void __asan_store##size(unsigned long addr)		\
   1202 	{							\
   1203 		kasan_shadow_check(addr, size, true, __RET_ADDR);\
   1204 	}							\
   1205 	void __asan_store##size##_noabort(unsigned long);	\
   1206 	void __asan_store##size##_noabort(unsigned long addr)	\
   1207 	{							\
   1208 		kasan_shadow_check(addr, size, true, __RET_ADDR);\
   1209 	}
   1210 
   1211 ASAN_LOAD_STORE(1);
   1212 ASAN_LOAD_STORE(2);
   1213 ASAN_LOAD_STORE(4);
   1214 ASAN_LOAD_STORE(8);
   1215 ASAN_LOAD_STORE(16);
   1216 
   1217 void __asan_loadN(unsigned long, size_t);
   1218 void __asan_loadN_noabort(unsigned long, size_t);
   1219 void __asan_storeN(unsigned long, size_t);
   1220 void __asan_storeN_noabort(unsigned long, size_t);
   1221 void __asan_handle_no_return(void);
   1222 
   1223 void
   1224 __asan_loadN(unsigned long addr, size_t size)
   1225 {
   1226 	kasan_shadow_check(addr, size, false, __RET_ADDR);
   1227 }
   1228 
   1229 void
   1230 __asan_loadN_noabort(unsigned long addr, size_t size)
   1231 {
   1232 	kasan_shadow_check(addr, size, false, __RET_ADDR);
   1233 }
   1234 
   1235 void
   1236 __asan_storeN(unsigned long addr, size_t size)
   1237 {
   1238 	kasan_shadow_check(addr, size, true, __RET_ADDR);
   1239 }
   1240 
   1241 void
   1242 __asan_storeN_noabort(unsigned long addr, size_t size)
   1243 {
   1244 	kasan_shadow_check(addr, size, true, __RET_ADDR);
   1245 }
   1246 
   1247 void
   1248 __asan_handle_no_return(void)
   1249 {
   1250 	/* nothing */
   1251 }
   1252 
   1253 #define ASAN_SET_SHADOW(byte) \
   1254 	void __asan_set_shadow_##byte(void *, size_t);			\
   1255 	void __asan_set_shadow_##byte(void *addr, size_t size)		\
   1256 	{								\
   1257 		__builtin_memset((void *)addr, 0x##byte, size);		\
   1258 	}
   1259 
   1260 ASAN_SET_SHADOW(00);
   1261 ASAN_SET_SHADOW(f1);
   1262 ASAN_SET_SHADOW(f2);
   1263 ASAN_SET_SHADOW(f3);
   1264 ASAN_SET_SHADOW(f5);
   1265 ASAN_SET_SHADOW(f8);
   1266 
   1267 void __asan_poison_stack_memory(const void *, size_t);
   1268 void __asan_unpoison_stack_memory(const void *, size_t);
   1269 
   1270 void
   1271 __asan_poison_stack_memory(const void *addr, size_t size)
   1272 {
   1273 	size = roundup(size, KASAN_SHADOW_SCALE_SIZE);
   1274 	kasan_shadow_Nbyte_fill(addr, size, KASAN_USE_AFTER_SCOPE);
   1275 }
   1276 
   1277 void
   1278 __asan_unpoison_stack_memory(const void *addr, size_t size)
   1279 {
   1280 	kasan_shadow_Nbyte_markvalid(addr, size);
   1281 }
   1282 
   1283 void __asan_alloca_poison(const void *, size_t);
   1284 void __asan_allocas_unpoison(const void *, const void *);
   1285 
   1286 void __asan_alloca_poison(const void *addr, size_t size)
   1287 {
   1288 	const void *l, *r;
   1289 
   1290 	KASSERT((vaddr_t)addr % KASAN_ALLOCA_SCALE_SIZE == 0);
   1291 
   1292 	l = (const uint8_t *)addr - KASAN_ALLOCA_SCALE_SIZE;
   1293 	r = (const uint8_t *)addr + roundup(size, KASAN_ALLOCA_SCALE_SIZE);
   1294 
   1295 	kasan_shadow_Nbyte_fill(l, KASAN_ALLOCA_SCALE_SIZE, KASAN_STACK_LEFT);
   1296 	kasan_mark(addr, size, roundup(size, KASAN_ALLOCA_SCALE_SIZE),
   1297 	    KASAN_STACK_MID);
   1298 	kasan_shadow_Nbyte_fill(r, KASAN_ALLOCA_SCALE_SIZE, KASAN_STACK_RIGHT);
   1299 }
   1300 
   1301 void __asan_allocas_unpoison(const void *stkbegin, const void *stkend)
   1302 {
   1303 	size_t size;
   1304 
   1305 	if (__predict_false(!stkbegin))
   1306 		return;
   1307 	if (__predict_false((uintptr_t)stkbegin > (uintptr_t)stkend))
   1308 		return;
   1309 	size = (uintptr_t)stkend - (uintptr_t)stkbegin;
   1310 
   1311 	kasan_shadow_Nbyte_fill(stkbegin, size, 0);
   1312 }
   1313